3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Provide a table of the asset discovery methods your product supports, listing the asset types each method can find.
Why it matters. If the product lacks a discovery method the buyer depends on, the assets that only that method finds stay outside the inventory and never receive a risk score.
Good answer
- Table covers active network discovery, agents, cloud and virtualization connectors, directory imports and [CMDB] imports
- Each method is mapped to specific asset types such as servers, workstations, network devices, cloud instances and printers
- States which methods need an on-premises sensor or collector
Red flags
- A list of method names with no asset types mapped to them
- Claims that one method finds "all assets"
- Methods that depend on a third-party product are not identified as such
2. Provide a table of the operating systems and versions your product supports, showing for each whether agent-based assessment and authenticated network scanning are available.
Why it matters. Hosts running an operating system that neither the agent nor the authenticated scan supports get only banner-level unauthenticated checks. Missing patches on those hosts go undetected.
3. Provide a table of the cloud workload types your product assesses for vulnerabilities, such as virtual machines, machine images, container images, container registries, Kubernetes clusters and serverless functions, showing for each [cloud provider] whether assessment is agentless, agent-based or both.
Why it matters. A product that covers virtual machines but not container images or serverless functions leaves whole classes of cloud workloads unassessed. The buyer may not find these gaps until after rollout.
Capability areas
Asset Discovery & Inventory (10)
Finding managed, unmanaged and shadow assets, building a single asset identity across sources, and reconciling the inventory against our CMDB. Excludes how assets are then assessed for vulnerabilities, which is covered under scanning and cloud coverage.
Scanning & Detection Methods (13)
Authenticated and unauthenticated network scanning, agent-based and agentless assessment, credential handling, scan scheduling, scan safety on fragile systems, detection accuracy, and new-check release speed. Excludes cloud-native, container and OT-specific assessment, and web application scanning (application security testing is a separate category; its findings are ingested under AGG).
Cloud, Container & Ephemeral Workloads (11)
Assessment of cloud accounts, virtual machine images, container images and registries, Kubernetes clusters, serverless functions and short-lived workloads that exist between scan windows. Excludes cloud misconfiguration and identity risk except where it feeds vulnerability findings, which are covered under exposure context.
External Attack Surface (8)
Discovery and assessment of internet-facing assets, domains, certificates and exposed services as an outside attacker would see them, including attribution of unknown assets to an owner. Excludes internal network scanning.
OT, IoT & Non-Standard Devices (9)
Identification and assessment of operational technology, IoT, medical and network devices, including passive methods that avoid disrupting controllers. Excludes standard servers, workstations and cloud workloads.
Risk-Based Prioritization (14)
How findings are ranked beyond base severity using exploit-prediction scores, known-exploited catalogs, in-the-wild and ransomware association, exploit maturity, and threat intelligence freshness. The transparency and tunability of the scoring model are in scope. Excludes business context inputs, which are covered under asset criticality.
Asset Criticality & Business Context (9)
How asset criticality, data sensitivity, business service mapping, compensating controls and ownership are captured, kept current and applied to risk scores. Excludes the external threat signals used in prioritization.
Exposure Context & Attack Paths (11)
Attack-path analysis, choke-point identification, unification of vulnerability, misconfiguration and identity findings, and validation that an exposure is reachable or exploitable in our environment. Excludes the base prioritization score and remediation workflow.
Remediation Workflow & Ticketing (13)
Grouping findings by fix, owner assignment, bidirectional ticketing with ITSM and work-tracking tools, patch and configuration management hooks, and remediation guidance. Excludes verification of closure, exceptions and SLA tracking.
Closed-Loop Verification, Exceptions & SLAs (10)
Confirmation by re-assessment that a fix landed, handling of findings that reappear, risk acceptance and exception workflow with expiry, governance of false-positive suppressions (who may suppress, review and expiry), and SLA tracking with escalation. Excludes ticket creation and routing, and detection accuracy itself, which is under SCN.
Findings Aggregation & Normalization (10)
Ingestion of findings from third-party scanners, application security tools and cloud security tools, with de-duplication, normalization to a common vulnerability and asset model, and conflict handling between sources. Excludes generic API and connector availability, which is covered by the integration module.
Reporting & Program Metrics (9)
Mean-time-to-remediate and risk burndown trends, role-based and owner-level views, executive reporting, and reports that support our compliance mandates. Excludes the vendor's own certifications.
Questions about this package
How many Vulnerability Management Platforms RFP questions are there?
127 solution questions in 12 capability areas: 27 for the RFI, 65 for the RFP and 35 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.